Skip to main content

Legal · Privacy

Privacy Policy

Last updated: August 18, 2026

Coshippr Inc., doing business as Potluck ("Potluck," "we," "us") builds local-first AI software. This policy explains what we collect, why, and what we do not. We wrote it to be read, not to hide behind.

The short version

Most of what you do in Potluck never reaches us. Your prompts, your chats, your files, and your saved memory stay on your own device. Our cloud service only handles your account, your membership, and billing. When you route a request across the mesh, you choose the scope, and we tell you on every request what left your machine.

1. What this covers

This policy covers the Potluck desktop application, the website at trypotluck.ai, and the account, membership, and billing services we run at api.trypotluck.ai. It does not cover third parties we link to or integrate with, who have their own policies (see Section 6).

Potluck is early software under active development. Practices may change as the product develops; we will update this policy and the "last updated" date when they do.

2. What we collect

Account information. When you create an account we collect your email address (used for passwordless magic-link sign-in) and, if you set one, a display name. We store a hashed session token so you stay signed in.

Membership and billing. If you become a member or pay dues, our payments processor (Stripe) handles your card details. We do not see or store full card numbers. We keep a record of your membership status, plan, and billing events (for example, a successful payment or a cancellation).

Technical and security data. Our servers log basic request metadata (such as IP address and timestamps) to operate the service, prevent abuse, and rate-limit sign-in requests. If you opt into error reporting, our error-monitoring tool may capture technical diagnostics; we mask email addresses in those logs.

Community. If you use our community forum, that account and your posts are handled there (see Section 6).

Website. The website uses privacy-respecting, cookieless analytics that do not track you across sites or build an advertising profile. The website itself does not collect your email; account sign-in happens in the desktop app.

3. What we do NOT collect

We designed Potluck so the sensitive parts stay with you. We do not collect, and our cloud service never receives:

  • Your prompts or chat messages.
  • Your saved memory or task notes (these live in a database file on your own machine).
  • Your files, codebases, or model weights.

The desktop app talks to a local engine on your own computer for inference and memory. Our cloud service is only for account, membership, and billing data.

4. The mesh: what leaves your machine

Potluck lets you choose, per request, where a request runs. We show you a receipt on each reply describing what left your device.

  • Local (default). The request runs on your machine. Nothing leaves it.
  • Your machines / trusted circle. The request may run on other machines you own or explicitly trust, reached over an encrypted WireGuard connection. It does not pass through us in readable form.
  • Open public pool (opt-in). If you choose this scope, your prompt is sent to another member's machine to generate the reply. Routing is blinded: the request carries no account identity, so the serving member does not learn who sent it. To generate a reply, the serving machine does process the text of your prompt. We are honest that this is not cryptographic privacy in the current version; it rests on blinded routing, a verified client, and network rules, not on math that hides the content from the machine doing the work. Do not send anything to the open pool that you would not want a stranger's computer to process.

5. How we use information

We use the information above to:

  • Provide and maintain the service, including signing you in and running the network.
  • Process membership and payments.
  • Keep the service secure, prevent abuse, and debug problems.
  • Communicate with you about your account, service changes, and support requests.

We do not sell your personal information. We do not use your content to train models without your explicit opt-in.

6. Third parties we rely on

We use a small number of service providers to run Potluck. Each processes only what it needs and under its own terms:

  • Stripe — payments and billing.
  • Resend — sending transactional email (such as your sign-in link).
  • Sentry — error monitoring (email addresses masked), if enabled.
  • Discourse — the community forum, if you use it.
  • Vercel — hosting the trypotluck.ai website.
  • Fly.io / DigitalOcean — hosting our account and coordination services.
  • Cloudflare — DNS, content delivery, and release-file hosting.

This list may change as the service grows; we will keep it current.

7. Cookies and tracking

We use a strictly necessary session cookie (or an equivalent token) to keep you signed in to your account. The website uses cookieless analytics and does not use advertising or cross-site tracking cookies.

8. Data retention

We keep account and billing records for as long as you have an account and as long as we are required to for legal, tax, and accounting purposes. Security logs are kept for a limited period and then discarded. Memory and content stored on your device are retained until you delete them, which you can do directly in the app.

9. Your rights and choices

You can:

  • Access or correct your account information by contacting us.
  • Delete your account by contacting us; deleting the app and its local data removes the on-device parts yourself.
  • Manage billing through the Stripe customer portal linked in the app.

Depending on where you live, you may have additional rights under laws such as the GDPR (EU/UK) or the CCPA/CPRA (California), including rights to access, delete, correct, or port your personal information, and to object to certain processing. We honor these requests and do not discriminate against you for exercising them. To make a request, contact us at the address below.

10. Security

We use encryption in transit, hashed session tokens, and access controls, and we designed the product to minimize what we hold in the first place. No system is perfectly secure, but keeping the sensitive data on your device is our main protection.

11. Children

Potluck is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their personal information.

12. International users

We operate from the United States. If you use Potluck from outside the US, you understand that the limited account and billing data we hold is processed in the US and other countries where our providers operate.

13. Changes to this policy

We will update this policy as the product and our practices change, and we will revise the "last updated" date. For material changes we will make a reasonable effort to notify members.

14. Contact

Questions or requests: hello@trypotluck.ai Coshippr Inc., doing business as Potluck, a Delaware corporation, c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713.